176 Followers
194 Following
757 Posts
Security engineer at @srlabs in Berlin
Websitehttps://louismerl.in

We don't need to hack your AI Agent to hack your AI Agent …and we don't need an AI agent for that either :)

Via a large enterprise's AI assistant, we obtained access to several million Entra identities and all chat logs including attachments — no prompt injection or model tricks required.

For all we know, the poor agent was not at fault and may not have even been able to witness what was happening.

https://srlabs.de/blog/hacking-ai-agent

#AI #AIhacking #VulnerabilityDisclosure #ResponsibleDisclosure

We don't need to hack your AI Agent to hack your AI Agent - SRLabs Research

We strolled through an enterprise AI assistant's backend, helped ourselves to full application takeover and access to every chat log, and had a Microsoft Entra ID dump for dessert — no prompt injection, no model tricks, no AI expertise required.

SRLabs
Having fun with my kid playing with the delay time on the #microrack
#openhardware #synth

Pokémon Go players thought they were catching Pikachus.

They were actually building the nervous system for robot civilization.

500M humans. 30B images. Zero consent forms.

The game was the harvest.
https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/

How Pokémon Go is giving delivery robots an inch-perfect view of the world

Niantic's AI spinout is training a new world model using 30 billion images of urban landmarks crowdsourced from players.

MIT Technology Review

What's the state of digital sovereignty for our academic landscape?

Inspired by a similar post looking at digital sovereignty of municipalities, I explored what messaging infrastructure universities rely on. Sadly, many have switched to hyper scalars but few large universities keep running their own email infrastructure. Germany, Austria, France does not look too bad and lead by example.

[Note that the assessment is based on a simple MX records comparison against a list of known scalars, I don't yet check SPF records or guesstimate the SMTP software/version, this may be done in a future version.]

Check out the interactive map: https://nebelwelt.net/gannimo/unimx/

The MacBook Neo is such an interesting machine that it coaxed a thousand-word-essay out of me: https://samhenri.gold/blog/20260312-this-is-not-the-computer-for-you/
“This Is Not The Computer For You” · Sam Henri Gold

Sam Henri Gold is a product design engineer building playful, useful software.

🌺 Sur @pixelsfr des initiatives concrètes pour se passer des Big techs américaines, avec la campagne « DéMAILnagement », le collectif CHATONS et mes chouchous de l’auto-hébergement communautaire sans data center, DeuxFleurs et Club1.

https://www.lemonde.fr/pixels/article/2026/03/14/j-ai-decide-de-faire-mes-adieux-a-gmail-ces-initiatives-pour-se-passer-des-big-tech-americaines_6671142_4408996.html

« J’ai décidé de faire mes adieux à Gmail » : ces initiatives pour se passer des Big Tech américaines

Accompagnés par des associations, des particuliers et des collectifs abandonnent les Gafam au profit d’autres solutions, libres, sobres, locales et non marchandes.

Le Monde

Computing in the year 2029 as depicted in UNIX WORLD magazine, 1985.

#UNIX

If you're in Berlin, I'll be exhibiting some art at arkaoda next week (March 11 7pm). More info heeere https://ra.co/events/2387223

Embedded systems security engineer / cryptographer open to contracts or permanent roles. Based in Lausanne, CH.

Background in embedded crypto libraries, PKI, smartcard middleware, software security research.

For contracts: direct preferred, remote-friendly. For permanent: Lausanne-commutable or remote.

Languages: English, French, some German.

DM or email preferred.

#cryptography #embeddedsystems #PKI #infosec #contractor #hiring #FediHire #fedihireme #fedihired #jobsearch #rust